Umbra Wiki defense defense/D3-SCA
Back to wiki

D3-SCA — System Call Analysis

provenance: imported · ATT&CK: T1007 T1010 T1012 T1016 T1016.001 T1016.002 T1018 T1033 T1036 T1036.005 T1047 T1049 T1053 T1053.002 T1053.003 T1053.005 T1053.006 T1053.007 T1055 T1055.001 T1055.003 T1055.004 T1055.005 T1055.008 T1055.013 T1055.014 T1057 T1074 T1074.001 T1082 T1106 T1113 T1124 T1134 T1134.004 T1140 T1218 T1218.001 T1218.002 T1218.003 T1218.005 T1218.011 T1218.013 T1220 T1497 T1497.003 T1505 T1505.001 T1518 T1518.001 T1546 T1546.009 T1546.010 T1548 T1548.002 T1548.004 T1555 T1555.003

D3-SCA: System Call Analysis

MITRE D3FEND countermeasure

What it does

Analyzing system calls to determine whether a process is exhibiting unauthorized behavior.

Attacks this counters

The chain in this corpus runs CVE → CWE → CAPEC → ATT&CK technique, which ends at what an adversary does. This is the hop after: what stops it.

Source